Skill
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle is benign. It correctly implements security best practices such as using `jq` for safe JSON escaping of user input, enforcing HTTPS and TLS 1.2 for API calls, and using environment variables for the API key. The `SKILL.md` file is transparent about security considerations and provides good advice to the user. There is no evidence of malicious intent, data exfiltration, unauthorized execution, or prompt injection attempts against the agent. The API endpoint `open.bigmodel.cn` is legitimate for Zhipu AI.
